Executive brief
Microsoft Office, a widely-used productivity suite for creating documents and spreadsheets, contains a flaw that could allow an attacker to read sensitive information from a user's system over a network. If exploited, this could lead to exposure of confidential business data or personal information embedded in Office files or system memory.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Office, allowing an attacker to access memory regions beyond intended boundaries. The vulnerability can be triggered over a network without requiring prior authentication. By crafting a malicious Office document or exploit payload, an attacker can leak sensitive information from the affected system's memory. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office <UNKNOWN>
Timeline
- 2026-09-08: disclosed